Sungrow WiNet-S Hardcoded Password Vulnerability Allowing Firmware Decryption

Vulnerability

A vulnerability exists in Sungrow WiNet-S version WINET-SV200.001.00.P027 and earlier, due to a hardcoded password in the WiNet WebUI. This password can be used to decrypt firmware update files, which are otherwise encrypted. The presence of this hardcoded password could potentially be exploited to manipulate the firmware update process.

Impact

Exploitation of this vulnerability allows for unauthorized decryption of firmware update files, which could lead to further manipulation or exploitation of the device.

Remediation

Users are advised to upgrade to WiNet-S version WINET-SV200.001.00.P028 or higher.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.